Post-quantum readiness is not a prediction exercise about the exact arrival date of a powerful quantum computer. It is a data-lifetime and migration problem that already affects decisions about sensitive information, long-lived systems and future procurement.
Why the risk starts now
A cryptographically relevant quantum computer could undermine widely used public-key cryptography, including mechanisms used for key establishment and digital signatures. The machine does not need to exist today for exposure to begin.
Under a “harvest now, decrypt later” strategy, an adversary records encrypted traffic or acquires protected datasets now and retains them until future capability makes decryption possible. Information that must remain confidential for many years—government records, intellectual property, health data, strategic communications and critical-infrastructure designs—therefore has a risk window longer than the migration window.
If data must remain secret beyond the time needed to migrate the systems protecting it, the post-quantum problem has already started.
Digital signatures create a related integrity risk. Code signing, device identity, certificates and software-update chains depend on cryptographic trust that may be embedded in products with long operational lives.
A migration timeline organisations can plan against
NIST finalised its first three post-quantum cryptography standards in August 2024: ML-KEM for key establishment, plus ML-DSA and SLH-DSA for digital signatures. The UK National Cyber Security Centre then set practical milestones for large organisations and critical operators.
NIST publishes the first three final PQC standards, giving organisations stable foundations for implementation and testing.
Complete estate-wide discovery, define migration goals, identify suppliers and produce an initial migration plan.
Complete the highest-priority migrations and refine a thorough roadmap for the remaining estate.
Move systems, services and products away from quantum-vulnerable public-key cryptography.
Timeline sources: UK NCSC migration guidance and NIST Post-Quantum Cryptography project.
The hidden migration challenge
Replacing an algorithm is only one part of the work. Cryptography is distributed through applications, protocols, identities, certificates, hardware roots of trust, cloud services, devices and supplier products. Many organisations cannot yet produce a reliable inventory of where vulnerable public-key algorithms are used or which business outcomes depend on them.
Migration can also change message sizes, performance, interoperability and certificate or key-management processes. Long-lived hardware and third-party platforms may follow different upgrade cycles. Without visibility, the programme becomes reactive: unknown scope, competing owners, procurement delays and operational risk.
What crypto-agility requires
Crypto-agility is the governed ability to discover, assess and change cryptography without losing control of the systems it protects. It combines technical architecture with ownership, lifecycle rules, supplier coordination and evidence that changes have propagated.
Locate algorithms, keys, certificates, protocols, libraries, hardware and external dependencies.
Connect cryptography to data lifetime, system criticality, business impact and threat exposure.
Identify long-lived secrets, critical signatures, difficult dependencies and systems with constrained upgrade paths.
Introduce abstraction, configurable algorithms and approved patterns that make controlled change possible.
Test interoperability, performance, rollback and evidence of completed migration.
What organisations should do now
- Assign an accountable executive and technical owner for post-quantum readiness.
- Identify information whose confidentiality lifetime extends into the 2030s.
- Build a cryptographic inventory around critical systems and long-lived data first.
- Ask strategic suppliers which products use vulnerable cryptography and when PQC support will arrive.
- Add crypto-agility and PQC requirements to new architecture, procurement and contract renewals.
- Test one representative migration path using standardised algorithms and record operational lessons.
No authoritative body can provide an exact date for a cryptographically relevant quantum computer. That uncertainty is not a reason to wait: the standards exist, migration takes years, and the data at greatest risk may already be collected.